IP Library › Granted Patent US 11,252,192
Granted Patent B1
US 11,252,192 · App. 16/370,201 · Granted Feb 15, 2022

Dynamic security scaling

Inventors: Philip Kwan (San Jose, CA); Sudeep Padiyar (Santa Clara, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/20H04L12/4641H04L41/0806H04L41/0816
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,252,192
App. No.
16/370,201
Granted
Feb 15, 2022
Kind
B1
Abstract

An indication that a change implicating security in a network environment needs to be made is received. In response to receiving the indication, a first set of instructions for reconfiguring at least one network device is determined, and a second set of instructions for reconfiguring at least one security device is determined. At least one network device and at least one security device are, respectively, caused to be reconfigured in accordance with the respective first and second set of instructions.

Claims (28)

1. A system, comprising:

a processor configured to:

in response to receiving an indication that a change associated with adjusting a capacity to provide security services to network traffic in a network environment needs to be made, determine, by the system, reconfiguration instructions comprising: a set of network device instructions for reconfiguring a network device and a set of security appliance instructions for reconfiguring a first security appliance, wherein the network device and the first security appliance are different types of devices, and wherein as a result of applying the respective reconfiguration instructions, either (1) an amount of network traffic provided by the network device to the first security appliance will increase, or (2) at least a portion of network traffic that would otherwise be provided by the network device to the first security appliance will instead be provided to a second security appliance; and

cause the network device to be reconfigured in accordance with the set of network device instructions and cause the first security appliance to be reconfigured in accordance with the set of security appliance instructions, including by using a plugin to translate an action into a vendor specific command; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the indication is received in response to a provisioning of an application in the network environment.

3. The system of claim 1 , wherein the indication is received in response to an overloading of a device.

4. The system of claim 1 , wherein the reconfiguration instructions include instructions for rebalancing network fabric.

5. The system of claim 1 , wherein the reconfiguration instructions include instructions for rebalancing a load on the first security appliance.

6. The system of claim 1 , wherein the indication is received in response to the second security appliance joining the network environment.

7. The system of claim 1 , wherein the indication is received in response to identification of a potential security threat from a node.

8. The system of claim 7 , wherein the reconfiguration instructions cause traffic from the node to be dynamically redirected to the first security appliance for inspection.

9. The system of claim 1 , wherein the first security appliance is connected in a service VTEP.

10. The system of claim 1 , wherein the reconfiguration instructions comprise provisioning instructions.

11. The system of claim 1 , wherein the reconfiguration instructions include instructions for redirecting a VXLAN tunnel.

12. A method, comprising:

in response to receiving an indication that a change associated with adjusting a capacity to provide security services to network traffic in a network environment needs to be made, determining, by a system, reconfiguration instructions comprising: a set of network device instructions for reconfiguring a network device and a set of security appliance instructions for reconfiguring a first security appliance, wherein the network device and the first security appliance are different types of devices, and wherein as a result of applying the respective reconfiguration instructions, either (1) an amount of network traffic provided by the network device to the first security appliance will increase, or (2) at least a portion of network traffic that would otherwise be provided by the network device to the first security appliance will instead be provided to a second security appliance; and

causing the network device to be reconfigured in accordance with the set of network device instructions and causing the first security appliance to be reconfigured in accordance with the set of security appliance instructions, including by using a plugin to translate an action into a vendor specific command.

13. The method of claim 12 , wherein the indication is received in response to a provisioning of an application in the network environment.

14. The method of claim 12 , wherein the indication is received in response to an overloading of a device.

15. The method of claim 12 , wherein the indication is received in response to the second security appliance joining the network environment.

16. The method of claim 12 , wherein the indication is received in response to identification of a potential security threat from a node.

17. The method of claim 12 , wherein the first security appliance is connected in a service VTEP.

18. The method of claim 12 , wherein the reconfiguration instructions include instructions for redirecting a VXLAN tunnel.

19. The method of claim 12 , wherein the reconfiguration instructions include instructions for rebalancing network fabric.

20. The method of claim 12 , wherein the reconfiguration instructions include instructions for rebalancing a load on the first security appliance.

21. The method of claim 16 , wherein the reconfiguration instructions cause traffic from the node to be dynamically redirected to the first security appliance for inspection.

22. The method of claim 12 , wherein the reconfiguration instructions comprise provisioning instructions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2019
From: KWAN, PHILIP; PADIYAR, SUDEEP
To: PALO ALTO NETWORKS, INC.
Reel/Frame 049365/0375 →
Continuity (1)
Provisional Application 62738850 · Sep 28, 2018
Cited By (7)
US 12,218,980 US 12,602,483 US 12,615,182 US 12,621,207 US 12,681,733 US 12,711,206 US 12,725,170